Philips and GE Probe Clop Ransomware Claims Tied to PTC Software Flaw

General Electric and Philips are investigating claims by the Clop ransomware gang that it breached their systems and stole sensitive data. GE says it is aware of the claim and is working to assess the potential issue, while Philips confirms that an attempted compromise of a specific enterprise server holding internal data has been identified and contained, with no impact on customer environments.

The two tech giants join oil major Shell, which is also investigating a potential security incident after Clop claimed to have stolen 89GB of its data. All three companies appear on Clop's leak site as part of a batch of 43 new victims, likely targeted in data theft attacks exploiting a critical improper input validation vulnerability, tracked as CVE-2026-12569, affecting internet-exposed PTC Windchill and PTC FlexPLM instances.

PTC says its platforms are widely used by high-profile companies in aerospace, defense, automotive, heavy machinery, retail, and medtech, with more than 30,000 customers globally. Clop claims it stole a wide range of data from the compromised systems, including backups, project plans, facility photos, drawings, diagrams, and blueprints. PTC began releasing security patches on June 17 and urges customers to review their environments for indicators of compromise.

Read More at the original source →